VYPR

dnsmasq

by Red Hat

CVEs (2)

  • CVE-2020-14312MedFeb 6, 2021
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option…

  • CVE-2026-12969MedJun 23, 2026
    risk 0.34cvss 5.3epss 0.00

    An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker…